> For the complete documentation index, see [llms.txt](https://sovietbeast-writeups.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sovietbeast-writeups.gitbook.io/writeups/ctfs/fetch-the-flag-2023/web/you-wouldnt-steal-a-flag.txt.md).

# You wouldn't steal a /Flag.txt

Website is static page without much functionality, but there is one *weird* behaviour as it loads some `base64` encoded files names.

<figure><img src="https://133742081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDnToeJfxVb7jBS1Pupch%2Fuploads%2FLfiqXJ5gxkmIp6eBEtol%2FPasted%20image%2020231027182823.png?alt=media&amp;token=c2586232-ee9e-4b8c-82cc-470297b1334c" alt=""><figcaption></figcaption></figure>

In the website source code there are two kinds of imports, ones that are encoded in plain english, and one that are encoded in base64.

<figure><img src="https://133742081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDnToeJfxVb7jBS1Pupch%2Fuploads%2FUV5e7mxbdBZJQsGzAtNT%2FPasted%20image%2020231027182831.png?alt=media&amp;token=13b5ec40-4c8e-44fa-bcbc-a39baf026cca" alt=""><figcaption></figcaption></figure>

There are also two different error messages for `404 File Not Found` if path starts with `assets` there are default `Flask` 404 page.&#x20;

<figure><img src="https://133742081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDnToeJfxVb7jBS1Pupch%2Fuploads%2F7WEWSMTDSuEA6CnQWN7Y%2FPasted%20image%2020231027183135.png?alt=media&amp;token=7ce7b606-83a1-4a32-980a-2b60ac661728" alt=""><figcaption></figcaption></figure>

But if path starts with anything different there is custom `Error: 404!` message. That indicates there are two different logics for accesing this paths.&#x20;

<figure><img src="https://133742081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDnToeJfxVb7jBS1Pupch%2Fuploads%2FW2Z7c0fEiv3L3pjeGIZs%2FPasted%20image%2020231027183214.png?alt=media&amp;token=92b0d235-4b33-4c4c-a795-3d18216f4779" alt=""><figcaption></figcaption></figure>

When sending data encoded as base64 that utylize basic `path traversal` thta isn't start with *assets* there is custom message error.&#x20;

<figure><img src="https://133742081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDnToeJfxVb7jBS1Pupch%2Fuploads%2Fk3clVTGijbZtfdYqfG3L%2FPasted%20image%2020231027183316.png?alt=media&amp;token=fc12ed4f-056b-4f6d-b45e-aeba4aa8eae3" alt=""><figcaption></figcaption></figure>

But when accesing it from any path that starts with *assets* path traversal works

```bash
echo -n  'assets/vendor/purecounter/../../../../../../../../../../flag.txt' | base64 -w0
```

<figure><img src="https://133742081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FDnToeJfxVb7jBS1Pupch%2Fuploads%2F24oEZEkS8hlDKjotc2TC%2FPasted%20image%2020231027183352.png?alt=media&amp;token=7f151edb-56ed-4280-9073-f9402b6f32a4" alt=""><figcaption></figcaption></figure>
